Threat reportPhishingTL-2026-3037
RMM tools distributed via phishing: ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud and N-able abused for remote access
RMM tools distributed via phishing (TL-2026-3037) is a high-severity phishing campaign, first published 2026-10-01. It has no confirmed attribution, affects ConnectWise ScreenConnect (abused, not vulnerable), maps to 11 MITRE ATT&CK techniques (T1036.005, T1036.008, T1059.003), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-3037
- Threat ID
- TL-2026-3037
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- finance, legal, enterprise, managed-service-providers
- Target regions
- Global, North America
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in RMM tools distributed via phishing
Malware and tooling: BlackCat (Windows), BlackCat - S1068, MEDUSA - S1220, PLAY Ransomware, ConnectWise - S0591, FleetDeck.io, Jump Cloud, ScreenConnect, SimpleHelp
How RMM tools distributed via phishing works
AhnLab ASEC reports ongoing phishing campaigns, first seen in January 2026, that deliver legitimate Remote Monitoring and Management (RMM) agents (ScreenConnect, FleetDeck, Datto RMM, SimpleHelp, JumpCloud, N-able) to victims. Because the binaries are legitimately signed tools without malware signatures, they evade traditional detection while giving operators interactive remote access.
AhnLab Security Intelligence Center (ASEC) published on 2026-10-01 an analysis of phishing campaigns that distribute six legitimate RMM products instead of custom malware. The activity was first detected in January 2026 and is ongoing. The tools are real vendor software configured with attacker-controlled tenant, server or account identifiers, so the endpoint shows a signed, trusted agent beaconing to an attacker-controlled instance.
Delivery varies by tool. ScreenConnect is delivered through LNK, BAT and VBS email attachments with deceptive names (Dropbox.SharedfilePDF.LNK, ZoomSetup-V.7.3.Bat, Wire Receipt Form_pdf.Vbs); the C2 server and port are embedded in the installer execution arguments, and ScreenConnect.ClientSetup.msi was fetched from attacker hosts such as 216.250.252.58:8040 and admin.lukiku.lol (relay.lukiku.lol observed as relay). FleetDeck is delivered through PDF documents with clickable links that download an installer; a deployment ID appended to the end of the file is passed as the -deploymentID argument (fleetdeck_agent_svc.exe -deploymentID <uuid> -askForName=0). ASEC associates FleetDeck use with Scattered Spider, which previously distributed DragonForce ransomware. Datto RMM is delivered through PDFs showing a fake Adobe Acrobat Pro update prompt that downloads AdrAcroPro11.2_3D_client.Exe; the CagService.Exe.Config file holds an AccountUid that identifies the operator. SimpleHelp is delivered through HTML phishing scripts, with the C2 server address stored hex-encoded in the sg_servers configuration entry; ASEC notes SimpleHelp abuse in Play, Medusa and ALPHV (BlackCat) intrusions. JumpCloud is delivered through phishing pages impersonating Adobe security documents; batch malware downloads and runs the agent with the operator's CONNECT_KEY argument. N-able is delivered through batch malware disguised as DocuSign Viewer that shows a fake DocuSign page while installing the agent; its settings.Ini contains the operator email mark@hessattorneys.co.za.
Corroborating public reporting shows the same technique class at scale: ANY.RUN research (published 2026-08-25) tracked 425 phishing-kit URLs across 240 hosts between 5 February and 29 July 2026 in 46 countries (about 45% US), with 94% of hosts live for a single day, and lures impersonating tax agencies, Social Security, Adobe, invoices, shipping and DocuSign. Red Canary and Zscaler (2025-09-12) documented ITarian, PDQ, SimpleHelp and Atera delivered via fake browser updates, fake Teams/Zoom/Excel updates, e-invite lures and government-form lures, with dual-RMM redundancy (SimpleHelp followed by ScreenConnect) and follow-on payloads such as HijackLoader and DeerStealer. Netlas (2026-06-05) lists MuddyWater, Hive affiliates, Storm-1811 and RansomHub as RMM abusers. No CVE is involved; the risk is abuse of legitimate functionality, so detection must rely on allow-listing approved RMM products and tenant IDs, and on behavioral telemetry (unexpected RMM installs, LNK/BAT/VBS launching installers, msiexec fetching from non-vendor hosts).
MITRE ATT&CK techniques used in TL-2026-3037
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1036.008 Masquerade File Type
Execution
T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.001 Malicious Link; T1204.002 Malicious File
Command and Control
T1219.002 Remote Desktop Software
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
Affected products and versions in RMM tools distributed via phishing
- ConnectWise — ScreenConnect (abused, not vulnerable)
- FleetDeck — FleetDeck Agent (abused, not vulnerable)
- Datto (Kaseya) — Datto RMM (abused, not vulnerable)
- SimpleHelp — SimpleHelp (abused, not vulnerable)
- JumpCloud — JumpCloud Agent (abused, not vulnerable)
- N-able — N-able RMM (abused, not vulnerable)
- Microsoft — Windows (target platform)
Remediation for RMM tools distributed via phishing
Immediate actions
- Block the listed domains, IP addresses and URLs at proxy, DNS and email gateways
- Hunt endpoints for ScreenConnect, FleetDeck, Datto RMM, SimpleHelp, JumpCloud and N-able agents that are not in the approved RMM inventory
- Quarantine email attachments of type LNK, BAT, VBS and HTML with document-themed names (Dropbox, Zoom, Wire Receipt, DocuSign, Adobe)
- Isolate hosts where an unapproved RMM agent was installed and rotate credentials used on them
Workarounds
- Block egress to unapproved RMM relay infrastructure
- Verify sender trust and inspect intermediate redirects in linked URLs before opening
Longer-term hardening
- Maintain an allow-list of sanctioned RMM products and tenant/instance/account identifiers, and alert on any other
- Use application control (WDAC/AppLocker) to block unapproved remote-access software
- Restrict script-host and LNK execution from user-writable and mail-attachment paths
- Train users that software-update prompts inside PDFs and fake Adobe/DocuSign pages are phishing
Timeline of RMM tools distributed via phishing
- AhnLab ASEC reports the first detection of the RMM-via-phishing campaigns in January 2026; activity continues through the report date
- ANY.RUN's tracking window of RMM phishing-kit URLs begins (425 URLs across 240 hosts through 2026-07-29, 46 countries, ~45% US)
- Netlas publishes Weaponized RMM hunting guide citing a 277% year-over-year rise in RMM abuse and listing MuddyWater, Hive, Storm-1811 and RansomHub use
- End of ANY.RUN's observation window; 94% of 240 hosts were seen on only one day, indicating rapid infrastructure rotation
- ANY.RUN publishes research on RMM phishing spanning 46 countries with tax, Social Security, Adobe, invoice, shipping and DocuSign lures
- AhnLab ASEC publishes analysis of six legitimate RMM tools (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able) distributed via phishing, with IOCs
Sources cited for RMM tools distributed via phishing
- RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able) - AhnLab ASEC
- RMM Phishing Campaign Spans 46 Countries as Attackers Abuse Trusted IT Tools - eSecurityPlanet (ANY.RUN research)
- Phishing RMM tools - Zscaler ThreatLabz
- Phishing RMM tools - Red Canary Intelligence
- Weaponized RMM: Hunting the Adversary Abuse of Remote Monitoring Tools - Netlas
- Phishing Campaigns Drop RMM Tools for Remote Access - Infosecurity Magazine
Detection coverage for TL-2026-3037
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3037 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.